Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

SSL VPN XGS 4500 - TCP RST

Hi there,

we recently migrated from UTM to XGS4500, almost everythings working as expected excelt for SSL VPN with the sophos client.

I have setup the SSL profile according to the sophos youtube video but I can't connect. The client sticks at "veryfing authentication" and wireshark tells me that the TCP session gets a RST. 

I switched to UDP, but no success, I tried override hostname and also the WAN ip - same issue. The firewall rule is also configured as shown in the video. 

We use AD users for authentication (STAS).

Currently I am out of ideas.

Regards

Marcel



This thread was automatically locked due to age.
Parents
  • Hello Marcel,

    Adding to what Bharat, has mentioned, make sure you don't have a DNAT rule configured with service ANY or the Port used for SSL VPN. 

    You could confirm also what Firewall Rule the traffic is hitting from the client using the GUI PCAP of the XG

    Regards,

Reply
  • Hello Marcel,

    Adding to what Bharat, has mentioned, make sure you don't have a DNAT rule configured with service ANY or the Port used for SSL VPN. 

    You could confirm also what Firewall Rule the traffic is hitting from the client using the GUI PCAP of the XG

    Regards,

Children
No Data